Chilling Discoveries: Unpacking Vulnerabilities in Copeland XWEB Pro Controllers
ID: 6b0665d7-7bbb-569a-86c7-1024f4c8b433
STIX ID: report--6b0665d7-7bbb-569a-86c7-1024f4c8b433
Feed Name: Claroty Team82
Team82 (Claroty) disclosed 23 vulnerabilities in the Copeland XWEB Pro supervisory controller—21 rated high—including a Lua authentication bypass (CVE-2026-25085), a deterministic daily admin password mechanism (CVE-2026-21718), and multiple OS command injection flaws that together allow unauthenticated root remote code execution; researchers demonstrated a working PoC and a physical spoilage scenario against field controllers and coordinated remediation with Copeland resulting in firmware update v1.13.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
